# Parsing syslogs from different Cisco devices to Logstash

**URL:** https://discuss.elastic.co/t/parsing-syslogs-from-different-cisco-devices-to-logstash/74680
**Category:** Logstash
**Created:** [February 10, 2017, 3:22pm UTC](https://discuss.elastic.co/t/parsing-syslogs-from-different-cisco-devices-to-logstash/74680 "2017-02-10T15:22:48Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![Rinat](https://avatars.discourse-cdn.com/v4/letter/r/dec6dc/32.png) [@Rinat](https://discuss.elastic.co/u/Rinat)
#### Post date: [February 10, 2017, 3:22pm UTC](https://discuss.elastic.co/t/parsing-syslogs-from-different-cisco-devices-to-logstash/74680/1 "2017-02-10T15:22:48Z")

</div>

My scenario is as follows: rsyslog server collects logs from different Cisco gears. It then forwards it to Logstash as syslogs type.

Are there any configuration examples for Logstash to filter all the different Cisco devices? Any examples of filters/config files?

Running 5.1 on RHEL 6.

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [February 13, 2017, 10:39am UTC](https://discuss.elastic.co/t/parsing-syslogs-from-different-cisco-devices-to-logstash/74680/2 "2017-02-13T10:39:29Z")

</div>

There are a bunch of Cisco patterns bundled with Logstash:

> <https://github.com/logstash-plugins/logstash-patterns-core/blob/v4.0.2/patterns/firewalls>

---

<div class="post-metadata">

### Author: ![Rinat](https://avatars.discourse-cdn.com/v4/letter/r/dec6dc/32.png) [@Rinat](https://discuss.elastic.co/u/Rinat)
#### Post date: [February 13, 2017, 6:41pm UTC](https://discuss.elastic.co/t/parsing-syslogs-from-different-cisco-devices-to-logstash/74680/3 "2017-02-13T18:41:44Z")

</div>

Thanks!

My understanding is that I need to include those lines inside grok filter? How would I go about it?

Best regards,

Rinat

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 13, 2017, 6:42pm UTC](https://discuss.elastic.co/t/parsing-syslogs-from-different-cisco-devices-to-logstash/74680/4 "2017-03-13T18:42:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
